RFC Passive Scan Disclaimer
Last Updated & Effective Date: September 26, 2026
Orbit Security is engineered exclusively as a defensive, passive perimeter reconnaissance and attack surface hygiene tool. Our systems operate in accordance with the U.S. Department of Justice Revised Charging Policy under the Computer Fraud and Abuse Act (18 U.S.C. ยง 1030), which protects good-faith security research and defensive posture auditing designed to correct vulnerabilities before malicious adversaries exploit them.
1. Technical RFC Standards Compliance
All reconnaissance procedures executed by Orbit Security (including the client-side DNS-over-HTTPS scanner and the Orbit Recon engine) strictly query open, public standards without altering, injecting, or manipulating remote server states:
2. Explicit Prohibitions & Anti-Exploitation Guarantees
Orbit Security incorporates strict hardcoded architectural bounds to ensure it never crosses into unauthorized access or offensive exploitation:
- No Payload Injection: We never transmit SQL injection, cross-site scripting (XSS), remote code execution (RCE), or binary payloads.
- No Credential Stuffing or Brute-Forcing: We never attempt to crack passwords, bypass logins, or test dictionary credentials.
- No Dangling Subdomain Registration: When a dangling CNAME record is identified (e.g. Unbounce, S3, GitHub Pages), Orbit Security never registers or claims the target asset. We flag the orphaned pointer so the legitimate domain owner can remove it.
- No Data Exfiltration: Probes for sensitive file exposure (such as
/.envor/.git/HEAD) stream a maximum of 256 KB to identify fingerprint needles. Orbit Security never logs, stores, or extracts proprietary database passwords, cryptographic keys, or customer records. - No Denial of Service (DoS): Queries are rate-limited, pooled, and throttled to prevent server degradation or bandwidth exhaustion.
3. Legal Precedent & Legal Alignment
Following the landmark U.S. Supreme Court decision in Van Buren v. United States (2021), accessing publicly available endpoints and information that does not require bypassing password-protected barriers or technological access controls does not constitute a violation of the Computer Fraud and Abuse Act. Orbit Security operates exclusively on the external, public perimeter.
4. Regulatory Standards & Compliance Alignment
Orbit Security's automated heuristics are explicitly mapped to recognized web security and email deliverability frameworks:
Automates mandatory verification of SPF alignment, DKIM signatures, and strict DMARC (p=quarantine or p=reject) to prevent bulk email rejection.
Assists ecommerce agencies in confirming Content-Security-Policy (CSP) script authorization and HTTP header tampering shields across checkout perimeters.
Continuously tracks dangling DNS pointers to decommissioned cloud assets (AWS S3, Shopify, Unbounce) to eliminate hostile subdomain takeovers.
Provides objective third-party monthly PDF audit documentation required by cyber insurance underwriters to substantiate proactive perimeter care.
5. Agency-Client Safe Harbor Contract Rider (Copy-Paste for Agency MSAs)
AGENCY SHIELDAgencies subscribing to Orbit Security may incorporate the following standard provision into their client Master Services Agreements (MSAs), Web Care Plans, or Maintenance SOWs to establish clear contractual authority:
"Client authorizes Agency and its automated security telemetry partners (including Orbit Security) to conduct continuous, non-intrusive external perimeter reconnaissance, DNS authentication analysis (SPF/DKIM/DMARC), subdomain routing checks, and public HTTP header verification across Client's digital domains and staging properties. Client acknowledges that all surveillance is conducted passively or via standard RFC-compliant HTTP queries without payload execution or access-control bypasses, and serves solely to maintain attack surface hygiene."
6. Domain Exclusion & Opt-Out Request
If you are the verified administrative contact of a domain and wish to permanently block your domain from being queried by Orbit Security users or our automated sentinel fleet, you may request immediate inclusion in our global exclusion registry.
Email carsonmail009@gmail.com with the subject "Domain Exclusion Request" from an authorized domain address (e.g., security@yourdomain.com). Exclusions are processed and locked within 24 hours.